The FileInfo plugin before 2.22 for Ghisler Total Commander allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via (1) a large Size value in the Archive Member Header of a COFF Archive Library file, (2) a large Number Of Symbols value in the 1st Linker Member of a COFF Archive Library file, (3) a large Resource Table Count value in the LE Header of a Linear Executable file, or (4) a large value in a certain Object field in a Resource Table Entry in a Linear Executable file.
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Link | Tags |
---|---|
http://blogs.cisco.com/security/talos/fileinfo-plugin-dos | |
http://www.securitytracker.com/id/1033004 | vdb entry |
http://www.securityfocus.com/bid/75955 | vdb entry |
http://totalcmd.net/plugring/fileinfo.html | |
http://www.kb.cert.org/vuls/id/813631 | third party advisory us government resource |